[wp-trac] [WordPress Trac] #56101: Need to use esc_html escaping function instead of esc_attr.
WordPress Trac
noreply at wordpress.org
Fri Jul 1 15:02:28 UTC 2022
#56101: Need to use esc_html escaping function instead of esc_attr.
------------------------------+---------------------
Reporter: chintan1896 | Owner: (none)
Type: defect (bug) | Status: new
Priority: normal | Milestone: 6.1
Component: Comments | Version: 2.7
Severity: normal | Resolution:
Keywords: has-patch commit | Focuses:
------------------------------+---------------------
Changes (by SergeyBiryukov):
* keywords: has-patch => has-patch commit
* version: 3.1 => 2.7
Comment:
Hi there, thanks for the patch! It looks good to me and seems to match the
escaping of comment author's email in
`WP_Comments_List_Table::column_author()`.
This was not introduced in [15955] though, it dates back to [9098] / #7435
for WP 2.7, followed by [11109] and [11204].
--
Ticket URL: <https://core.trac.wordpress.org/ticket/56101#comment:3>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform
More information about the wp-trac
mailing list